I have had the same issue after upgrading from 16.x.You have to create an Alias (Firewall -> View -> Aliases) and create an alias called WANIP with the primary IP address of your router (so the WAN Address).After that change the rule that has WAN Address in it and set the Destination address to your newly created alias. After that everything starts working.It seems that the bug is that instead of WAN Address being used, the WAN NET is being used in the port forward.